Microsoft Releases Eight Security Updates
Juha-Matti Laurio writes "After a very uncommon break in March Microsoft has just published 8 new security updates. Almost all updates that are a part of the monthly release cycle are rated as 'Critical.' New Windows Shell vulnerability, named as MS05-016 is only 'Important,' but Windows XP Service Pack 2 is affected too, however. This is not the first time when there was something to fix at Shell32.dll.
Vulnerabilities in TCP/IP that could allow remote code execution and denial of service at cumulative bulletin MS05-019 are affecting SP2 too.
Windows Kernel, Exchange, MSN Messenger, Word (Office) and Internet Explorer get their updates as well."
... but after using the "windows update" utility in XP and 2000/2003 server for some time, and being a newbie to fedora (new servers in my home lab), i find the MS utilities muuuuuch easier to use than the fedora update manager. once i say no to an update, that choice stays "no" ... i have to always say no to unwanted updates in fedora (even tho they're on my ignore list). am i a feeble n00b, or could the linux distros learn a thing or two from MSFT?
nothing worth possessing isn't possessed. or something.
Glad I don't do "Auto Install"...hidden way at the bottom of the list of things Windows wanted to update was...
Update for Background Intelligent Transfer Service (BITS) 2.0 and WinHTTP 5.1 (KB842773)
Download size: 694 KB, 1 minute
This software updates the Background Intelligent Transfer Service (BITS) to v2.0 and updates WinHTTP. These updates help ensure an optimal download experience with new versions of Automatic Updates, Windows Update, and other programs that rely on BITS to transfer files using idle network bandwidth.
How is this critical?
last night, i got a popup message saying "updates were applied to your system and it will be rebooted in 5 minutes" - i tried to kill that process but it kept respawning. is that related to these patches? weird, i thought i had autoupdate disabled..
--
http://unk1911.blogspot.com
I'm more of a scenario 3 guy.
3) Ah, so this is how I've been vunerable for the last month...
At least it's only one month max, but still, we have to wait that long for completed fixes to be released just to make the process seem regular.
I know some people like the regular thing, I would prefer the choice however.
I always seem to have at least one windows box at home ... and quite frankly I'm glad slashdot gives me the heads up for updates. Its because of this that i was able to completly avoid the whole sasser etc aound of worms on my machine. I see the heads up, and in a few weeks i see the havoc that they unleashed on the net. then i have to go to my girlfriends place and fix her machine because she doesn't read slashdot and god only knows she isn't going to listen to me!
I'm wondering too. Every month they have security updates for all their OS'es. It's known that it takes them time to patch things, but here they're actually doing it, so you can't blame them.
There's thousands of security updates to thousands of apps every month. It's a normal part of software development to fix bugs and problems and push patches. But we don't hear about those...
This is not newsworthy whatsoever. Just download and apply the patches. Nothing to see here.
Five servers so far, and all of them have worked after the update. I'm far from a MS fan, but I have no problem admitting when they've done a good job.
The scary thing is that this fact is worthy of a post, and is informative.
Patches that do not break anything should be the rule, not the exception.
Keep in mind the fact that Windows XP consists of roughly 45 million lines of code. Considering this, I think it puts into perspective what a gargantuan task testing and patching truly is, and gives me a little more understanding of holes in the OS.
Why is this news at all ?
Patches up
I have mod points and I am not afraid to use them